← ClaudeAtlas

review-securitylisted

Security audit for vulnerabilities, secrets, and unsafe patterns. Use before releases, after adding auth code, or when reviewing third-party integrations.
nielsmadan/skills · ★ 0 · Code & Development · score 75
Install: claude install-skill nielsmadan/skills
<!-- Generated from https://github.com/nielsmadan/agentic-coding — edits here are overwritten. --> # Review Security Security audit for common vulnerabilities and unsafe patterns. ## Usage ``` /review-security # Review context-related code /review-security --staged # Review staged changes /review-security --unpushed # Review files changed across all unpushed commits /review-security --changed # Review unstaged changes /review-security --all # Full codebase audit (parallel agents) ``` ## Scope | Flag | Scope | Method | |------|-------|--------| | (none) | Context-related code | Files from the current conversation context: any files the user has discussed, opened, or that you have read/edited in this session. If no conversation context exists, ask the user to specify files or use `--staged`/`--changed`/`--all`. | | `--staged` | Staged changes | `git diff --cached --name-only` | | `--unpushed` | Files changed across unpushed commits | `git diff --name-only $(git rev-list HEAD --not --remotes \| tail -1)^..HEAD` | | `--changed` | Unstaged changes | `git diff --name-only` | | `--all` | Full codebase | Glob source files, parallel agents | `--unpushed` derives its range from `git rev-list HEAD --not --remotes` (oldest unpushed commit's parent → HEAD). If nothing is unpushed, or there is no remote/upstream (or the range walks back to the root commit) so it can't be determined reliably, stop and ask the user to pick another scope. **Do NOT skip che